MinorCritical vulnerability
CVE-2026-52748 (CVSS 7.1)
NVD · officialPublished Sep 28, 2026Risk 23/100
The Kaon AR2140X router contains a vulnerability where the backup functionality is accessible without authentication. This allows an unauthenticated remote attacker to trigger a configuration backup and retrieve it in a form encrypted by a device-specific key. Triggering this function renders the router inoperable for a substantial period of time. This issue was identified in firmware versions up to 4.2.17. Status of newer versions remains unknown.
Technical details
CVSS
7.1
AV:AdjacentAC:LowPR:NoneUI:None
Evidence and sources
This record is attributed to NVD. Exploitation status and remediation guidance are kept separate from the vulnerability's technical severity.
Open primary source